Back Isc.Sans.Edu Microsoft Patch Tuesday for November 2025, (Tue, Nov 11th)
Today's Microsoft Patch Tuesday offers fixes for 80 different vulnerabilities. One of the vulnerabilities is already being exploited, and five are rated as critical.
Notable Vulnerabilities:
CVE-2025-62215 : This vulnerability is already being exploited. It is a privilege escalation vulnerability in the Windows Kernel. These types of vulnerabilities are often exploited as part of a more complex attack chain; however, exploiting this specific vulnerability is likely to be relatively straightforward, given the existence of prior similar vulnerabilities.
CVE-2025-60274 : A critical GDI+ remote execution vulnerability. GDI+ parses various graphics files. The attack surface is likely huge, as anything in Windows (Browsers, email, and Office Documents) will use this library at some point to display images. We also have a critical vulnerability in Direct-X CVE-2025-60716 . Microsoft classifies this as a privilege escalation issue, yet still rates it as critical.
CVE-2025-62199 : A code execution vulnerability in Microsoft Office. Another component with a huge attack surface that is often exploited.
Given the number and type of vulnerabilities, I would consider this patch Tuesday "lighter than normal". There are no "Patch Now" vulnerabilities, and I suggest applying these vulnerabilities in accordance with your vulnerability management program.
-- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter |
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
